cbcvebase.
CVE-2026-44231
published 2026-07-20

CVE-2026-44231: RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information…

PriorityP260critical9.1CVSS 3.1
AVNACLPRLUINSCCHILAL
EPSS
0.41%
34.2th percentile
RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an information disclosure and privilege escalation vulnerability in the REST 2.0 API. A privileged (non-administrative) user can obtain authentication credentials belonging to other users — including users with administrative privileges — and use those credentials to read data as those users via RT's feed endpoints. The same request that exposes the credentials also rotates them, invalidating previously-distributed feed URLs across the instance. This issue has been fixed in versions 5.0.10 and 6.0.3.

Affected

5 ranges
VendorProductVersion rangeFixed in
bestpracticalrequest_tracker< 5.0.105.0.10
bestpracticalrequest_tracker>= 6.0.0 < 6.0.36.0.3
bestpracticalrt< 5.0.105.0.10
bestpracticalrt
ubunturequest-tracker5

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
vendor_ubuntu4.6MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.